Tenda AC7是中国腾达(Tenda)公司的一款无线路由器。 Tenda AC7 V03.03.03.01_cn及之前版本存在跨站脚本漏洞,该漏洞源于Web管理界面存在输出编码不当,可能导致在受害者浏览器环境中注入任意HTML或JavaScript。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Shenzhen Tenda Technology Co., Ltd. | Tenda AC7 | ≤ 03.03.03.01_cn |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Shenzhen Tenda Technology Co., Ltd. | Tenda AC7 | 0 ~ 03.03.03.01_cn | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-24441 | Tenda AC7 Transmits Admin Credentials Without HTTPS Protection | |
| CVE-2026-24427 | Tenda AC7 Exposes Admin Credentials in Configuration Responses | |
| CVE-2026-24434 | Tenda AC7 Web Interface Lacks CSRF Protections for Admin Actions |
No comments yet